CVE-2018-1028 is a remote code execution vulnerability in Microsoft Office products, including Word, Excel, and SharePoint, stemming from improper handling of specially crafted embedded fonts by the Office graphics component. With a CVSS score of 8.8 (High), it can be exploited remotely with low attack complexity, requiring user interaction, and potentially leading to full compromise of confidentiality, integrity, and availability. While no public exploit code or active exploitation has been confirmed, its high FAUCET Risk Score of 96/100 and limited community discussion suggest a notable, though not widely publicized, threat. This vulnerability was addressed in Microsoft's April 2018 Patch Tuesday updates.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:excel_services:-:*:*:*:*:*:*:* | ||
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2013:sp1:*:*:*:*:*:* | ||
2013_rtCPE matchmatch criteria | cpe:2.3:a:microsoft:office:2013_rt:sp1:*:*:*:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2016:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:microsoft:office_2010:*:sp2:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.